gist.github.com
https://gist.github.com/leommxj/0a32afeeaac960682c5b7c9ca8ed070d CVE-2020-29164
MEDIUMNuclei
PacsOne Server <7.1.1 - Cross-Site Scripting
Record summary
CVE-2020-29164 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMPacsOne Server <7.1.1 - Cross-Site ScriptingCVSS 6.1
PacsOne Server (PACS Server In One Box) below 7.1.1 is vulnerable to cross-site scripting.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to PacsOne Server version 7.1.1 or later to mitigate this vulnerability.
WeaknessesCWE-79
Authorsgeeknik
Template tagscvecve2020pacsonexssrainbowfishsoftwarevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:rainbowfishsoftware:pacsone_server:*:*:*:*:*:*:*:*
https://gist.github.com/leommxj/0a32afeeaac960682c5b7c9ca8ed070d https://pacsone.net/download.htm https://nvd.nist.gov/vuln/detail/CVE-2020-29164 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-29164 pacsone.net
https://pacsone.net/download.htm